Stored Cross-Site Scripting Vulnerability in ProfilePress Plugin for WordPress
CVE-2024-1535
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1535?
The ProfilePress plugin for WordPress contains a stored cross-site scripting vulnerability that arises from inadequate input sanitization and output escaping of user-supplied attributes in its shortcodes. This flaw allows authenticated attackers with contributor-level or higher permissions to inject malicious scripts that will execute when other users access the affected pages. All versions up to and including 4.15.2 are impacted, making it crucial for site administrators to address this security risk to protect their users from potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress * <= 4.15.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved